Senior Incident Response Engineer
Sophos
Skill Required
Key highlights
- Required experience: 5+ years leading ransomware incident response investigations
- Key benefit: Remote-first working model (primary option for most employees)
- Notable requirement: Strong grasp of the MITRE ATT&CK framework
- Schedule: Friday to Tuesday, fixed morning shift 6am–3pm IST
- Desirable: Cybersecurity certifications such as CISSP or GCFA
- Benefit: Global wellbeing days and monthly wellbeing webinars
Role overview
Sophos is seeking an experienced Senior Incident Response Consultant to join its elite Incident Response (IR) team, which provides global organizations with comprehensive cyber threat response, forensic investigations, remediation guidance, and root cause analysis using industry-standard tools and Sophos technologies. In this role, you will lead incident response engagements, direct a team of consultants, conduct customer-facing calls and written updates, prioritize investigations, ensure threat neutralization, perform root cause analysis including data exfiltration assessment, and produce executive summary reports mapping events to the MITRE ATT&CK framework. The ideal candidate has extensive experience leading IR efforts, deep knowledge of cybersecurity threats, and strong executive communication skills.
Responsibilities
- Lead kick off calls with customers to understand their situation and identify initial response actions to contain the threat
- Provide guidance to customers on best practices following an incident
- Lead daily update calls for customers to deliver forensic findings
- Deliver concise email updates to customers between update calls
- Direct the forensic investigations, identify priorities, and delegate tasks to analysts
- Conduct multiple Rapid Response incidents concurrently
- Determine TTPs identified by analysts and add them to the threat intel platform
- Write clear and concise Executive Summary style reports in a timely manner
- Responsible for basic to moderate complexity projects that contribute to the development of the Sophos Rapid Response service
- Provide daily handover notes to teams located in different time zones, or when incident responsibility is being transferred to another Incident Lead
Requirements
- 5+ years of experience leading incident response investigations involving ransomware
- Experience leading BEC investigations
- Continuously learning and staying informed of the changing threat landscape
- Proven track record of successful neutralization and remediation of ransomware threats
- Excellent understanding of the Incident Response process
- Excellent understanding of cyber risks and able to qualify them to customers
- Excellent oral communication skills
- Strong written communication skills
- Ability to manage time effectively
- Able to delegate and prioritize tasks across multiple incidents
- Able to excel under stressful circumstances
- Occasionally willing to begin work early and/or stay late when warranted for customer engagements
- Strong grasp of the MITRE ATT&CK framework
- Enjoy mentoring and assisting in the development of junior analysts
- A team-player attitude with a willingness to share knowledge
- Ability to work on weekends and holidays
- Post-secondary education in Cybersecurity, comparable
Nice to have
- Cybersecurity certifications an asset (e.g. CISSP, GCFA, or similar)
- Experience with SIEM technology (e.g. Splunk, ELK, etc.)
- Willingness to work occasional overtime during peak times or holidays
- Experience writing SQL queries
- Experience writing PowerShell, Python, or Bash scripts
Benefits
- Sophos operates a remote-first working model, making remote work the primary option for most employees (some roles may necessitate a hybrid approach); applicants must have legal authorization to work in the jurisdiction where the position is posted without requiring employer sponsorship
- Employee-led diversity and inclusion networks that build community and provide education and advocacy
- Annual charity and fundraising initiatives and volunteer days for employees to support local communities
- Global employee sustainability initiatives to reduce environmental footprint
- Global fitness and trivia competitions to keep bodies and minds sharp
- Global wellbeing days for employees to relax and recharge
- Monthly wellbeing webinars and training to support employee health and wellbeing
- Great sense of fun and team spirit among colleagues
Additional details
- This role will involve working from Friday to Tuesday (Wednesday & Thursday would be off).
- It will involve working in fixed Morning Shift (6am to 3pm IST).
- Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services, headquartered in Oxford, U.K.
- Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies including endpoint, network, email, and cloud security, XDR, ITDR, and next-gen SIEM.
- Sophos goes to market with a global partner ecosystem including MSPs, MSSPs, resellers, distributors, marketplace integrations, and cyber risk partners.
- Originally posted on Himalayas.
- Sophos believes in the power of diverse perspectives to fuel innovation and encourages applicants who don't check every box to apply.
- Sophos is committed to a diverse and inclusive environment, ensuring equality of opportunity regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation.
- Sophos will hold CV or personal details for 12 months in accordance with its Privacy Policy; candidates can request deletion or update at any time.